purple-teaming

Plan and execute purple team exercises to validate security detections against MITRE ATT&CK techniques.

5|Updated Feb 2, 2026
One-click install
npx skills add https://github.com/dmaynor/dmaynor-skills-marketplace --skill purple-teaming
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: purple-teaming
Source: https://github.com/dmaynor/dmaynor-skills-marketplace/tree/main/plugins/purple-teaming/skills/purple-teaming
Command: npx skills add https://github.com/dmaynor/dmaynor-skills-marketplace --skill purple-teaming

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps security teams proactively test and improve their detection capabilities against real-world adversary techniques, ensuring their defenses are effective.

Core Features & Use Cases

  • Plan and Execute Exercises: Design and run purple team exercises using atomic or scenario-based methodologies.
  • Detection Validation: Test if security tools and processes correctly identify and alert on specific adversary actions.
  • Coverage Analysis: Map existing detections against the MITRE ATT&CK framework and identify gaps.
  • Use Case: A security team wants to ensure their SIEM can detect attempts to dump LSASS memory. They use this Skill to run an atomic test for T1003.001, observe the telemetry, and verify if their detection rule fires.

Quick Start

Use the purple-teaming skill to plan an exercise to test T1087.002 and T1003.001.

Frequently Asked Questions about purple-teaming

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate SIEM detections against MITRE ATT&CK adversary techniques?

Run atomic tests for specific techniques like T1003.001 to observe telemetry and verify if your detection rules fire. This skill facilitates both isolated technique testing and scenario-based attack chain execution to validate security tool detection capabilities.

What is the difference between atomic and scenario-based purple teaming exercises?

Map existing detections against the MITRE ATT&CK framework to identify coverage gaps. Conduct structured testing through purple team exercises to assess detection capabilities and track outcomes for comprehensive detection coverage assessment.

Can I use this skill to test specific MITRE ATT&CK techniques like LSASS memory dumping?

Use this skill to plan exercises targeting specific MITRE ATT&CK techniques like T1087.002 and T1003.001. It leverages the MITRE ATT&CK framework for scope definition, enabling structured testing to verify your security detections against real-world adversary techniques.

Do I need a cyber range environment to run purple team detection validation exercises?

The skill facilitates planning and executing purple team exercises for validating security detections against adversary techniques. It supports atomic and scenario-based methodologies using MITRE ATT&CK for scope definition and comprehensive detection coverage assessment.

How do I identify detection coverage gaps using adversary emulation?

Map existing detections against the MITRE ATT&CK framework and execute adversary emulation exercises to identify gaps. The skill enables comprehensive detection coverage assessment through structured testing and outcome tracking for both atomic and scenario-based methodologies.